
CVE-2026-75616
Proof-of-concept exploit for authenticated OS command injection in TP-Link Archer C20 v6 web management interface, executing root commands via BPA…

Proof-of-concept exploit for authenticated OS command injection in TP-Link Archer C20 v6 web management interface, executing root commands via BPA…

Domain-independent back end for rolling out software updates to constrained edge devices, controllers, and gateways over IP-based infrastructure,…

Proof-of-concept exploit for a buffer overflow vulnerability in Tenda AC8v4 router firmware (V16.03.34.09) via the SetNetControlList endpoint,…

Iot Camera 0day

Exploit for command injection vulnerability found in uhttpd binary from TP-Link Tapo c200 IP camera

A ESP32-S3–based usb keylogger with wifi, easy DIY-able with widely available hardware.

CVE-2018-19537

Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while…


PoC exploit chain for TP-Link Tapo C260 camera — CVE-2026-0651/0652/0653. Research by @spaceraccoon.

Python port of the Linksys tmUnblock.cgi RCE exploit

CVE-2024-3273 — Authorized Penetration Test Report D-Link DNS-320L NAS | Client: Otonata

CVE-2021-43469

Proof-of-concept exploit for authenticated command injection in Atlona AT-OME-RX21, allowing root-level command execution via the time configuration…

Analysis and PoC for D-Link DIR-890L RCE (CVE-2022-29778)

D-link AX1500 Vulnerability

Proof-of-concept exploit for CVE-2021-41730, demonstrating remote command execution in TENDA AC15/AC6 routers via unvalidated formSetIptv()…

CVE-2025-22912